Junglewise Threat Intelligence

CVE-2026-42977: Microsoft Windows Push Notifications race condition privilege escalation

CVE-2026-42977 · Severity: high · CVSS 7.8 · Published 2026-06-09

Technologies: Microsoft Windows Push Notifications. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows Push Notification service, which handles the delivery of real-time alerts and updates to applications. An attacker who already has limited access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to view sensitive data, install malicious software, or disrupt business operations.

Technical details

A race condition (CWE-362) exists in the Windows Push Notifications service due to improper synchronization when accessing shared resources. To exploit this, an attacker must first have local access to the system with low-level privileges. By successfully winning the race condition during concurrent execution, the attacker can achieve a privilege escalation, potentially gaining SYSTEM-level access. The vulnerability is characterized by high complexity (AC:H) and requires local authentication (PR:L), but it allows for a full compromise of confidentiality, integrity, and availability.

Affected products

  • Microsoft Windows Push Notifications

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References

Related threats